Skip to main content
Back to overview

NIS2 Registration: The Obligation Thousands of German Entities Still Have Not Met

By NIS2Certify
nis2-registrationbsicompliance-deadlinesmspentity-register
NIS2 Registration: The Obligation Thousands of German Entities Still Have Not Met

Germany's BSI estimates that about 29,500 entities fall under the NIS2 implementation act. The statutory registration deadline passed on 6 March 2026. By 30 June 2026, according to the BSI, 17,729 companies had registered. Measured against the BSI's own estimate, that leaves close to 12,000 organisations that are likely in scope, legally required to register, and have not.

The BSI's response so far has not been a fine. It has been a plain instruction on its NIS-2 page: the statutory deadline has passed, and anyone in scope who has not registered must do so immediately.

If you run an MSP or a consultancy with German clients, every unregistered client is already overdue. And registration is the one obligation you cannot fix in a sprint after the fact, because the register is timestamped.

Registration is a separate obligation from Article 21, and it lands first

Most compliance conversations start with the security measures. Risk analysis, incident handling, backups, MFA, supply chain. Article 21 work.

Registration sits somewhere else entirely. It comes from Article 3(4) of NIS2, which requires member states to establish a list of essential and important entities, and from Article 27, which requires certain digital infrastructure entities to submit identifying data. Member states operationalise this by making the entity register itself.

The practical difference matters: Article 21 obligations are assessed over time, in an audit, with room to show progress. Registration is binary. You are in the register on a given date, or you are not.

That is why registration is the first thing a supervisory authority looks at. It costs the regulator nothing to run a query against the register and compare it to a sector list from the chamber of commerce. Unregistered entities are the cheapest enforcement target in the whole directive.

Every member state runs its own register, on its own clock

There is no EU-wide NIS2 registration portal. Each transposition creates its own register, its own portal, and its own deadline — and those deadlines are now spread across a two-year window.

Germany: the NIS2UmsuCG took effect 6 December 2025, the BSI portal opened 6 January 2026, the statutory registration deadline was 6 March 2026, three months after entry into force (§ 33 BSIG). Registration is now overdue for anyone in scope who has not done it.

Belgium: registration with the Centre for Cybersecurity Belgium via Safeonweb@work closed on 18 March 2025. Belgium transposed early, so Belgian entities that only started NIS2 work in 2026 are already more than a year late.

The Netherlands: the Eerste Kamer adopted the Cyberbeveiligingswet on 7 July 2026. It enters into force on 15 August 2026, and registration via the NCSC entity register becomes mandatory from that date. Roughly 8,000 Dutch organisations are expected to fall in scope, supervised by the RDI across nine sectors.

Italy: registration under Legislative Decree 138/2024 runs through the ACN portal on an annual cycle, with a defined window each year rather than a one-off deadline.

For an MSP with clients in four countries, that is four portals, four legal bases, four sets of required data fields, and four dates. There is no version of this where a single spreadsheet column called "NIS2: yes/no" is enough.

NIS2 transposition by country

  • AustriaIn force
    • In force since October 1, 2026
    • Act: NISG 2026 (BGBl. I Nr. 94/2025)
    • Registration due December 31, 2026

    Authority: Federal Office for Cybersecurity · Source

  • NetherlandsIn force
    • In force since August 15, 2026
    • Act: Cyberbeveiligingswet (Stb. 2026, 187)
    • Registration required, no transition period

    Authority: NCSC (MijnNCSC) · Source

  • LuxembourgIn force
    • In force since May 10, 2026
    • Act: Law of 5 May 2026
    • Registration due July 10, 2026

    Authority: ILR (CSSF for finance) · Source

  • PolandIn force
    • In force since April 3, 2026
    • Act: UKSC (Dz.U. 2026 poz. 252)
    • Registration due October 3, 2026
    • Measures due April 3, 2027

    Authority: Minister Cyfryzacji (Wykaz KSC) · Source

  • PortugalIn force
    • In force since April 3, 2026
    • Act: Decree-Law 125/2025 (RJC)

    Authority: CNCS · Source

  • BulgariaIn force
    • In force since February 13, 2026
    • Act: Cybersecurity Act amendment (State Gazette No 17/2026)

    Authority: Ministry of e-Government · Source

  • MaltaIn force
    • In force since January 23, 2026
    • Act: S.L. 460.41

    Authority: Critical Infrastructure Protection Department · Source

  • SwedenIn force
    • In force since January 15, 2026
    • Act: SFS 2025:1506

    Authority: NCSC-SE · Source

  • EstoniaIn force
    • In force since January 1, 2026
    • Act: Cybersecurity Act (KüTS) amendment
    • Registration within 3 months

    Authority: RIA · Source

  • GermanyIn force
    • In force since December 6, 2025
    • Act: NIS2UmsuCG
    • Registration due March 6, 2026
    • 17,729 registered by June 30, 2026

    Authority: BSI · Source

  • CzechiaIn force
    • In force since November 1, 2025
    • Act: Act No 264/2025 Coll.
    • Registration within 60 days

    Authority: NÚKIB · Source

  • DenmarkIn force
    • In force since July 1, 2025
    • Act: NIS 2 Act No 434 of 6 May 2025
    • Registration due October 1, 2025

    Authority: Danish Agency for Societal Security · Source

  • SloveniaIn force
    • In force since June 19, 2025
    • Act: ZInfV-1 (OG 40/25)
    • Registration within 30 days

    Authority: URSIV · Source

  • CyprusIn force
    • In force since April 25, 2025
    • Act: Law 60(I)/2025

    Authority: Digital Security Authority · Source

  • FinlandIn force
    • In force since April 8, 2025
    • Act: Cybersecurity Act 124/2025
    • Registration due May 8, 2025
    • Measures due July 8, 2025

    Authority: Traficom (NCSC-FI) · Source

  • HungaryIn force
    • In force since January 1, 2025
    • Act: Act LXIX of 2024

    Authority: SZTFH · Source

  • SlovakiaIn force
    • In force since January 1, 2025
    • Act: Act No 366/2024 Coll.
    • Registration within 60 days

    Authority: NBÚ · Source

  • RomaniaIn force
    • In force since December 31, 2024
    • Act: GEO 155/2024 (Law 124/2025)
    • Registration within 30 days

    Authority: DNSC · Source

  • GreeceIn force
    • In force since November 27, 2024
    • Act: Law 5160/2024 (Gazette A' 195)

    Authority: National Cybersecurity Authority · Source

  • BelgiumIn force
    • In force since October 18, 2024
    • Registration due March 18, 2025

    Authority: CCB · Source

  • LithuaniaIn force
    • In force since October 18, 2024
    • Act: Law No XIV-2902

    Authority: NCSC (MoND) · Source

  • ItalyIn force
    • In force since October 16, 2024
    • Act: D.Lgs. 138/2024
    • Baseline measures due by October 2026 (entities listed in 2025)

    Authority: ACN · Source

  • LatviaIn force
    • In force since September 1, 2024
    • Act: National Cybersecurity Law

    Authority: National Cybersecurity Centre · Source

  • CroatiaIn force
    • In force since February 15, 2024
    • Act: Cybersecurity Act (OG 14/2024)

    Authority: NCSC (SOA) · Source

  • FranceNot yet transposed
    • Senate adopted the law on March 12, 2025
    • Regulator published its framework on March 17, 2026
    • Referred to the Court of Justice on July 8, 2026
    • Pre-registration open

    Authority: ANSSI · Source

  • SpainNot yet transposed
    • Draft bill approved on January 14, 2025
    • Referred to the Court of Justice on July 8, 2026
    • The NIS1 regime still applies

    Authority: CCN / INCIBE · Source

  • IrelandNot yet transposed
    • Referred to the Court of Justice on July 8, 2026
    • Bill not yet enacted

    Authority: NCSC Ireland · Source

Status as of September 28, 2026. Other member states: see the country-by-country timeline.

Your client's registration status is your problem before it is theirs

Here is the pattern we keep seeing. An MSP does solid technical work for a client — segmentation, EDR rollout, backup testing, MFA on everything that will take it. Twelve months of genuine security improvement.

Then the supervisory authority contacts the client, and the first question is not about MFA. It is: why are you not in the register?

The client's answer, almost always: "I assumed our IT provider handled that."

They are wrong about the legal position. Registration is the entity's own obligation and cannot be delegated away — the management body carries it under Article 20. But being legally right does not help you when a client's board is asking why nobody flagged it.

The fix is procedural, not technical. For every client, you need three data points on record: whether they are in scope, in which member states, and whether registration is confirmed with a reference number and date. If a client is out of scope, that determination needs to be written down with the reasoning — headcount, turnover, sector under Annex I or II — because "we decided they were out of scope" is not a defence unless you can show the assessment.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

The scope call is harder than it looks, and defaults toward "in"

Two things push more entities into scope than most consultants expect.

First, the size-cap rule is not the only route in. An entity is normally out unless it has 50 or more employees, or fewer than 50 with both annual turnover and balance sheet total above €10 million — but Article 2(2) pulls specific entities in regardless of size, including sole providers of a critical service in a member state, certain DNS and TLD entities, trust service providers, and public administration entities. Germany's transposition has been read broadly here, which is part of why the BSI's estimate landed near 29,500.

Second, group structures. Headcount and turnover thresholds are assessed with linked and partner enterprises included, following the EU SME definition. A 30-person Dutch subsidiary of a 900-person group is not a small entity for NIS2 purposes. We see this misread constantly, and it is the single most common reason an entity that believed it was out of scope receives a letter.

If you are running this determination across a client base, do it once, properly, and document it. A structured gap analysis makes the scope call defensible instead of a matter of opinion. You can start that in about ten minutes with our free quick scan, then take the output into a full assessment.

What happens after the deadline is not just a fine

The German framework allows fines of up to €10 million for particularly important entities that fail to take the required security measures, or up to 2% of worldwide turnover for a company with a total turnover above €500 million (§ 65 BSIG). A missed registration alone can cost up to €500,000. The big numbers get the headlines. It is rarely the thing that actually hurts.

Failure to register is an administrative offence that puts an entity on a supervisory authority's list as a known non-compliant party. That triggers a different posture: the authority now has a reason to look, and once it looks, it looks at Article 21 too. A registration failure is not an isolated penalty — it is an invitation to a full inspection of security measures the entity has likely not finished implementing.

Then it moves down the chain. Registration status is increasingly turning up in supplier due-diligence questionnaires under Article 21(2)(d). An unregistered supplier is a documented supply-chain risk for every essential entity it serves, which means the commercial consequence arrives before the regulatory one. Contract renewals get harder. New tenders get lost.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
▼
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
▼
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

What to do now

For German clients specifically, in this order.

Confirm scope. Sector under Annex I or II, size including group entities, and any Article 2(2) override. Write down the answer either way.

Check the register. If a client believes they registered, verify the confirmation and keep the reference. Registrations submitted with incomplete data have been bounced back, and some clients never noticed.

Register now. The BSI portal has been live since 6 January 2026. The submission itself takes under an hour once you have the entity data, contact points, and sector classification ready. There is no reason to stay among the unregistered.

For Dutch clients: 15 August is your date. The register goes live with the law. Get the entity data assembled now, because registering in week one is trivially easy and registering in month four is a conversation with the RDI.

For everyone else: build the register status column into your client tracker permanently. Registration is not a one-time task. Entity data changes, contact points change, and most member states require you to keep the register current — which means the obligation renews every time your client restructures, moves headquarters, or changes their security contact.

The organisations that get caught in the first enforcement wave will not be the ones with imperfect Article 21 controls. Almost nobody has perfect Article 21 controls yet. They will be the ones a regulator could identify with a single database query.

Related reading: NIS2 enforcement in Germany, the Dutch Cyberbeveiligingswet explained, and does NIS2 apply to me.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.